VYPR
Medium severity6.1NVD Advisory· Published Feb 9, 2021· Updated Jun 17, 2026

CVE-2021-21444

CVE-2021-21444

Description

SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack.

Affected products

5
  • cpe:2.3:a:sap:businessobjects_business_intelligence:410:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sap:businessobjects_business_intelligence:410:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*
  • Range: 410, 420, 430
  • SAP SE/SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad)v5
    Range: < 410

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.